RELEReleases

Defense Contractors Maintain Security Spending Despite CMMC Pause

The Defense Industrial Base continues to prioritize cybersecurity investment even as the Department of Defense pauses Phase 2 of the CMMC rollout. While some contractors have used the November 2026 scheduling shift as a reason to slow certification efforts, the majority report steady progress toward independent validation and compliance.

Bio & NewsOctober 1, 2026588 reads0

Redspin’s third annual study, "Committed to the Mission," reveals that 78.2% of surveyed defense organizations are either already Level 2 certified or actively pursuing it. Data suggests that the official enforcement of CMMC acted as a catalyst for firms that previously neglected defense posture under the long-standing DFARS 252.204-7012 requirements. Dr. Thomas Graham, vice president at Redspin, noted that the value of third-party validation remains a primary driver for investment, with 75% of respondents viewing Level 2 certification as beneficial regardless of contract eligibility.

Financial data reflects this commitment, as 75.4% to 84.4% of organizations reported no change in cybersecurity budgets. While a small segment of the industry—roughly 20%—has paused spending on certification, those investments in underlying infrastructure, such as cloud security and risk management tools, remain largely untouched. Furthermore, prime contractors continue to exert significant influence; only 23.3% of prime firms have relaxed certification requirements for their subcontractors, suggesting that private business mandates may ultimately outweigh the federal rollout timeline.

Comments (0)

Leave a comment

No comments yet. Be the first!